External Publication
Visit Post

PyPI package with 1.1M monthly downloads hacked to push infostealer

BleepingComputer [Unofficial] April 27, 2026
Source
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. [...]

Discussion in the ATmosphere

Loading comments...